From ef4387144eebaf7b0e862ddc1d942785f3a5541c Mon Sep 17 00:00:00 2001 From: Chen Jichang Date: Mon, 13 Jul 2026 20:39:36 +0800 Subject: [PATCH] test(aes): add aes psram ecc test --- .../mbedtls/port/aes/dma/esp_aes_dma_core.c | 4 - .../mbedtls/test_apps/.build-test-rules.yml | 1 + .../test_apps/mbedtls_ut/main/test_psa_aes.c | 99 +++++++++++++++++++ .../test_apps/mbedtls_ut/pytest_mbedtls_ut.py | 22 +++++ .../mbedtls_ut/sdkconfig.ci.psram_ecc | 5 + 5 files changed, 127 insertions(+), 4 deletions(-) create mode 100644 components/mbedtls/test_apps/mbedtls_ut/sdkconfig.ci.psram_ecc diff --git a/components/mbedtls/port/aes/dma/esp_aes_dma_core.c b/components/mbedtls/port/aes/dma/esp_aes_dma_core.c index 638cb90128c..f2fee0a16f5 100644 --- a/components/mbedtls/port/aes/dma/esp_aes_dma_core.c +++ b/components/mbedtls/port/aes/dma/esp_aes_dma_core.c @@ -43,10 +43,6 @@ #include "aes/esp_aes_gcm.h" #endif -#ifdef SOC_GDMA_EXT_MEM_ENC_ALIGNMENT -#include "hal/efuse_hal.h" -#endif /* SOC_GDMA_EXT_MEM_ENC_ALIGNMENT */ - /* Max size of each chunk to process when output buffer is in unaligned external ram must be a multiple of block size */ diff --git a/components/mbedtls/test_apps/.build-test-rules.yml b/components/mbedtls/test_apps/.build-test-rules.yml index 9eceef9148a..09991c37754 100644 --- a/components/mbedtls/test_apps/.build-test-rules.yml +++ b/components/mbedtls/test_apps/.build-test-rules.yml @@ -5,6 +5,7 @@ components/mbedtls/test_apps/mbedtls_ut: - if: CONFIG_NAME == "aes_no_hw" and SOC_AES_SUPPORTED != 1 - if: CONFIG_NAME == "psram" and SOC_SPIRAM_SUPPORTED != 1 - if: CONFIG_NAME == "psram_all_ext" and SOC_SPIRAM_SUPPORTED != 1 + - if: CONFIG_NAME == "psram_ecc" and (SOC_SPIRAM_SUPPORTED != 1 or SOC_PSRAM_DMA_CAPABLE != 1 or SOC_AES_SUPPORT_DMA != 1 or IDF_TARGET == "esp32s2") - if: CONFIG_NAME == "psram_all_ext_flash_enc" and SOC_SPIRAM_SUPPORTED != 1 - if: CONFIG_NAME == "psram_all_ext_flash_enc_f4r8" and IDF_TARGET != "esp32s3" - if: CONFIG_NAME == "ecdsa_sign" and SOC_ECDSA_SUPPORTED != 1 diff --git a/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_aes.c b/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_aes.c index e472b0f5c76..02a23d54bb5 100644 --- a/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_aes.c +++ b/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_aes.c @@ -1846,6 +1846,105 @@ TEST_CASE("mbedtls AES internal mem alignment tests", "[aes]") #ifdef CONFIG_SPIRAM_USE_MALLOC +#if CONFIG_SPIRAM_ECC_ENABLE && SOC_AES_SUPPORT_DMA +#define TEST_AES_PAYLOAD_LEN 53 + +struct aes_payload_sim_hdr { + uint8_t type; + uint8_t fc; + uint8_t seq; + uint8_t len; + uint8_t data[]; +} __attribute__((packed)); + +static void aes_psram_ecc_cfb128_inplace_test(void) +{ + const size_t pkt_len = sizeof(struct aes_payload_sim_hdr) + TEST_AES_PAYLOAD_LEN; + struct aes_payload_sim_hdr *pkt = heap_caps_aligned_alloc(16, pkt_len, PSRAM_DMA_CAPS); + uint8_t *backup = heap_caps_malloc(TEST_AES_PAYLOAD_LEN, INTERNAL_DMA_CAPS); + uint8_t key[16]; + uint8_t iv[16]; + psa_key_id_t key_id; + psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; + psa_status_t status; + size_t output_len; + size_t total_len; + + TEST_ASSERT_NOT_NULL(pkt); + TEST_ASSERT_NOT_NULL(backup); + TEST_ASSERT_TRUE(esp_ptr_external_ram(pkt)); + TEST_ASSERT_EQUAL_UINT32(0, (uintptr_t)pkt & 0x0F); + TEST_ASSERT_EQUAL_UINT32(sizeof(struct aes_payload_sim_hdr) & 0x0F, (uintptr_t)pkt->data & 0x0F); + + pkt->type = 0x13; + pkt->fc = 0x04; + pkt->seq = 1; + pkt->len = TEST_AES_PAYLOAD_LEN; + for (size_t i = 0; i < TEST_AES_PAYLOAD_LEN; i++) { + pkt->data[i] = 0x3C + (uint8_t)(i & 0x0F); + } + memcpy(backup, pkt->data, TEST_AES_PAYLOAD_LEN); + + memset(key, 0x5A, sizeof(key)); + memset(iv, 0xA5, sizeof(iv)); + iv[0] = 3; + + status = psa_crypto_init(); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + + psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT); + psa_set_key_algorithm(&attributes, PSA_ALG_CFB); + psa_set_key_type(&attributes, PSA_KEY_TYPE_AES); + psa_set_key_bits(&attributes, 128); + + status = psa_import_key(&attributes, key, sizeof(key), &key_id); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + + psa_cipher_operation_t operation = PSA_CIPHER_OPERATION_INIT; + status = psa_cipher_encrypt_setup(&operation, key_id, PSA_ALG_CFB); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + status = psa_cipher_set_iv(&operation, iv, sizeof(iv)); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len = 0; + status = psa_cipher_update(&operation, pkt->data, TEST_AES_PAYLOAD_LEN, pkt->data, TEST_AES_PAYLOAD_LEN, &output_len); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len += output_len; + status = psa_cipher_finish(&operation, pkt->data + output_len, TEST_AES_PAYLOAD_LEN - output_len, &output_len); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len += output_len; + TEST_ASSERT_EQUAL(TEST_AES_PAYLOAD_LEN, total_len); + + memset(iv, 0xA5, sizeof(iv)); + iv[0] = 3; + + psa_cipher_abort(&operation); + operation = (psa_cipher_operation_t)PSA_CIPHER_OPERATION_INIT; + status = psa_cipher_decrypt_setup(&operation, key_id, PSA_ALG_CFB); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + status = psa_cipher_set_iv(&operation, iv, sizeof(iv)); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len = 0; + status = psa_cipher_update(&operation, pkt->data, TEST_AES_PAYLOAD_LEN, pkt->data, TEST_AES_PAYLOAD_LEN, &output_len); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len += output_len; + status = psa_cipher_finish(&operation, pkt->data + output_len, TEST_AES_PAYLOAD_LEN - output_len, &output_len); + TEST_ASSERT_EQUAL(PSA_SUCCESS, status); + total_len += output_len; + TEST_ASSERT_EQUAL(TEST_AES_PAYLOAD_LEN, total_len); + + TEST_ASSERT_EQUAL_MEMORY(backup, pkt->data, TEST_AES_PAYLOAD_LEN); + psa_cipher_abort(&operation); + psa_destroy_key(key_id); + free(backup); + free(pkt); +} + +TEST_CASE("mbedtls AES PSRAM ECC CFB128 in-place test", "[aes][psram_ecc_dma]") +{ + aes_psram_ecc_cfb128_inplace_test(); +} +#endif // CONFIG_SPIRAM_ECC_ENABLE && SOC_AES_SUPPORT_DMA + void aes_psram_one_buf_ctr_test(void) { psa_key_id_t key_id; diff --git a/components/mbedtls/test_apps/mbedtls_ut/pytest_mbedtls_ut.py b/components/mbedtls/test_apps/mbedtls_ut/pytest_mbedtls_ut.py index dbdb9bd2303..611c1bcfa3d 100644 --- a/components/mbedtls/test_apps/mbedtls_ut/pytest_mbedtls_ut.py +++ b/components/mbedtls/test_apps/mbedtls_ut/pytest_mbedtls_ut.py @@ -5,6 +5,15 @@ from pytest_embedded import Dut from pytest_embedded_idf.utils import idf_parametrize from pytest_embedded_idf.utils import soc_filtered_targets +# esp32s2 has PSRAM DMA and AES DMA, but no PSRAM ECC Kconfig option. +PSRAM_ECC_DMA_TARGETS = [ + target + for target in soc_filtered_targets( + 'SOC_SPIRAM_SUPPORTED == 1 and SOC_PSRAM_DMA_CAPABLE == 1 and SOC_AES_SUPPORT_DMA == 1' + ) + if target != 'esp32s2' +] + @pytest.mark.generic @pytest.mark.temp_skip_ci(targets=['esp32h4'], reason='can not pass') # TODO: IDF-15675 @@ -53,6 +62,19 @@ def test_mbedtls_psram(dut: Dut) -> None: dut.run_all_single_board_cases(timeout=180) +@pytest.mark.generic +@pytest.mark.parametrize( + 'config', + [ + 'psram_ecc', + ], + indirect=True, +) +@idf_parametrize('target', PSRAM_ECC_DMA_TARGETS, indirect=['target']) +def test_mbedtls_psram_ecc(dut: Dut) -> None: + dut.run_all_single_board_cases(group='aes', timeout=180) + + @pytest.mark.flash_encryption_psram @pytest.mark.parametrize( 'config', diff --git a/components/mbedtls/test_apps/mbedtls_ut/sdkconfig.ci.psram_ecc b/components/mbedtls/test_apps/mbedtls_ut/sdkconfig.ci.psram_ecc new file mode 100644 index 00000000000..a9b5d4c749c --- /dev/null +++ b/components/mbedtls/test_apps/mbedtls_ut/sdkconfig.ci.psram_ecc @@ -0,0 +1,5 @@ +CONFIG_SPIRAM=y +CONFIG_SPIRAM_ECC_ENABLE=y +CONFIG_SPIRAM_MALLOC_ALWAYSINTERNAL=0 +CONFIG_FREERTOS_TASK_CREATE_ALLOW_EXT_MEM=y +CONFIG_ESP_INT_WDT_TIMEOUT_MS=800